Audit History
testing-strategy-builder - 9 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v9 Latest | Jul 23, 2026, 06:54 AM | No confirmed findings | 0 | No capability change |
| v8 | Jul 7, 2026, 06:26 PM | No confirmed findings | 0 | No capability change |
| v7 | Jul 6, 2026, 03:02 AM | No confirmed findings | 0 | No capability change |
| v6 | Jun 28, 2026, 10:37 AM | No confirmed findings | 2 | No capability change |
| v5 | Jan 16, 2026, 05:09 PM | No confirmed findings | 0 | No capability change |
| v4 | Jan 16, 2026, 05:09 PM | No confirmed findings | 0 | External commandsNetwork accessFilesystem access |
| v3 | Jan 10, 2026, 10:53 AM | No confirmed findings | 0 | No capability change |
| v2 | Jan 10, 2026, 10:53 AM | No confirmed findings | 0 | No capability change |
| v1 | Jan 10, 2026, 10:53 AM | No confirmed findings | 0 | Baseline |
Jul 23, 2026, 06:54 AM
All 69 static findings are false positives caused by Markdown formatting, test examples, placeholder network calls, and a fixed relative module path. The review found no prompt injection, exfiltration intent, unsafe dynamic execution, or path traversal.
Risk Factors
⚙️ External commands (49)
🌐 Network access (4)
📁 Filesystem access (1)
Jul 7, 2026, 06:26 PM
All static findings were adjudicated as false positives after reviewing the Markdown context. They are documentation examples, placeholder test data, setup commands, fenced-code markers, or testing snippets. No prompt injection, data exfiltration intent, or malicious execution behavior was found.
Risk Factors
⚙️ External commands (49)
🌐 Network access (4)
📁 Filesystem access (1)
Jul 6, 2026, 03:02 AM
All static findings were adjudicated as false positives caused by Markdown formatting, sample test commands, placeholder network examples, and QA template language. No prompt injection, data exfiltration intent, credential access, or executable malware behavior was found in the cited files.
Risk Factors
⚙️ External commands (49)
🌐 Network access (4)
📁 Filesystem access (1)
Jun 28, 2026, 10:37 AM
Static analysis flagged many shell, network, filesystem, and weak-crypto patterns, but reviewed evidence shows they are Markdown examples, templates, and testing guidance rather than executable skill logic. No prompt-injection language, data exfiltration intent, or malicious automation was found in the reviewed files. The skill is suitable for publication with low risk because users may copy commands or sample tests into their own projects.
Capability review items (2)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Static false positives ignored (1)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
⚙️ External commands (6)
🌐 Network access (4)
📁 Filesystem access (1)
Jan 16, 2026, 05:09 PM
Pure documentation skill containing only markdown files, code examples, and templates. No executable scripts, no network calls, no file system access beyond its own resources, and no environment variable access. The static scanner incorrectly flagged documentation examples showing testing tool commands (e.g., 'npm install jest') as backtick execution, and security testing references (e.g., discussing JWT, SQL injection testing) as cryptographic algorithm patterns. A prior Claude audit confirmed this skill contains only testing guidance and best practices.
Risk Factors
⚙️ External commands (114)
🌐 Network access (4)
📁 Filesystem access (1)
Jan 16, 2026, 05:09 PM
Pure documentation skill containing only markdown files, code examples, and templates. No executable scripts, no network calls, no file system access beyond its own resources, and no environment variable access. The static scanner incorrectly flagged documentation examples showing testing tool commands (e.g., 'npm install jest') as backtick execution, and security testing references (e.g., discussing JWT, SQL injection testing) as cryptographic algorithm patterns. A prior Claude audit confirmed this skill contains only testing guidance and best practices.
Risk Factors
⚙️ External commands (114)
🌐 Network access (4)
📁 Filesystem access (1)
Jan 10, 2026, 10:53 AM
Pure documentation skill containing only markdown files, code examples, and templates. No executable scripts, no network calls, no file system access beyond its own resources, and no environment variable access. Contains only testing guidance and best practices.
Jan 10, 2026, 10:53 AM
Pure documentation skill containing only markdown files, code examples, and templates. No executable scripts, no network calls, no file system access beyond its own resources, and no environment variable access. Contains only testing guidance and best practices.
Jan 10, 2026, 10:53 AM
Pure documentation skill containing only markdown files, code examples, and templates. No executable scripts, no network calls, no file system access beyond its own resources, and no environment variable access. Contains only testing guidance and best practices.